CVE · High

CVE-2026-40721 — Element Pack Pro [bdthemes-element-pack] < 9.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-40721 Element Pack Pro [bdthemes-element-pack] < 9.1.0 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 9.1.0 9.1.0 2026-06-17

CVE-2026-40721

A vulnerability has been discovered in Element Pack Pro plugins prior to version 9.0.7, which allows an attacker with contributor-level access to inject arbitrary local files into the application through a malformed input field. This flaw can be exploited by manipulating user input to bypass security checks and gain unauthorized access to sensitive data or system resources.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.